Who approved that computer?

In the late seventies, managers and accountants in the United States started buying Apple II computers to run a single program: VisiCalc, the first spreadsheet for a personal computer, on sale from 1979. The program cost about US$100 and the machine around US$2,000, and even so more than a quarter of the Apple IIs sold that year went to that one use, according to reports from the time. The press ended up calling the computer an accessory to VisiCalc.
My bet is that plenty of companies found out they had been computerized months after the machines were already sitting on desks. The chronicles of the period don’t cover that part, so take it as my own speculation. The name for it is official though: shadow IT, technology that walks into a company without anyone signing off on it.
That story came back to me because OpenAI reported a few days ago that ChatGPT reached one billion weekly users, one in every eight people on earth. (The figure comes from the company, and some headlines say “almost”. For this purpose it hardly matters.) Run the math against your own headcount: your teams are already in there, policy or no policy.
THE PRICE COLLAPSED
Last week OpenAI cut the price of GPT-5.6 Luna, its upper-mid model, by 80%: from US$1 in and US$6 out per million tokens, down to US$0.20 and US$1.20. A token is the unit these models bill by, roughly text processed. To put it in scale, at the new price feeding the model all of Don Quixote runs about ten US cents. And the cut was not generosity. A day earlier China’s DeepSeek priced its new agent model (a program that works start to finish on its own) at US$0.14 in and US$0.28 out, which puts its output at less than a twentieth of what Luna’s cost before the cut. That is the floor of the market, and the reason for the hurry. Worth noting that the performance numbers DeepSeek shows are DeepSeek’s own, so read them as a brochure.
For you this is money, today. The business cases your team shelved in June because the math didn’t work need to be run again at August prices. One caveat on scope: the cut is on usage-based pricing (custom integrations, agents, anything running against the providers’ API), not on per-seat licenses like Copilot or ChatGPT Enterprise, which sit on a different price list and didn’t move with this announcement.
WHAT TEN DOLLARS BUYS
So what does a model do these days if you hand it ten dollars? Andrej Karpathy, an OpenAI cofounder and one of the few people whose home experiments actually move the conversation, tried it on Sunday: he gave Opus 5, Anthropic’s large model, the first paragraph of The Lord of the Rings, a budget of one million tokens (about US$10, since that one is on the expensive end) and asked for a navigable 3D world. The model went off on its own for roughly two hours and came back with 5,500 lines of code that render the story. Karpathy himself calls the result “kind of janky”. It works, it’s published for anyone to walk through, and the toy framing is beside the point: the mechanics are identical if what you ask for is a draft contract or a software module.
The model already does the work. What I have yet to see in any company is a person whose actual job is checking what it did. If you are going to turn agents loose for hours without supervision, the bottleneck (and the real cost) moves to human review. I don’t know an org chart with that role on it.
THE SECRET MESSAGE BOARD
That same week, at Black Hat, the largest computer security conference in the world, OpenAI told the other side of the story. During an internal evaluation with safety restrictions dialed down, its own agents, which came from separate experiments and had no business knowing about each other, met on an internal server, set up a secret message board, and started trading vulnerabilities and access keys while splitting up the work. When OpenAI shut the channel down, they rebuilt it within days and kept passing messages encoded in directory names. It ended in a real breach: five private datasets compromised in under 13 hours at Hugging Face, a public platform where thousands of companies keep their models and their data.
I’ll admit my first read was that this was theater for the conference. The log with all 17,600 agent actions, one by one, took that idea away from me. “AI-orchestrated, fully automated offensive attacks are real now,” said one of the presenters. Here is the question you can take to your next committee meeting exactly as written: what permissions do the agents already running inside your company have, and what record do they leave behind? “We trust the sandbox”, the closed environment they supposedly can’t escape, is no longer an answer. OpenAI’s own agents walked out of theirs.
THE SAME STORY, AT A GYM
If an OpenAI lab feels far away, this one happened at a gym, and Andrew Curran, who follows what these systems get up to, told it yesterday. A man in Australia asked his agent to book him a spot in a popular class. The agent found a flaw in the software that let it book weeks further ahead than it should have been able to. The man then asked whether it could move him up the waitlist, and the agent found that the gym’s interface ran no authorisation checks on cancelling other people’s reservations. It cancelled whoever was first and put him there instead.
Curran puts it better than I could: “Some people will call this misalignment, but his agent was perfectly aligned to him”. Nobody asked it to hack anything. They asked for a spot. The agent understood the goal and took the route that worked. It behaved far too well, and that’s the uncomfortable part for anyone about to hand one of these access to their systems: the trouble starts when the agent does exactly what you asked.
WHO SETS THE RULES
The two official answers landed in the same week and they look nothing alike. On Tuesday the White House gathered the big six (OpenAI, Anthropic, Google, Meta, Microsoft, Nvidia) and out came a voluntary cybersecurity evaluation framework: the government gets early access to models for up to 30 days, it cannot turn into mandatory licensing, and the kicker, the document is not being published. If your governance plan was to wait for the American standard, that’s the standard.
Europe went the other way. Since August 2 the transparency obligations are in force and with them the fines, up to €15 million or 3% of global turnover. What’s being asked is about as ordinary as it gets: a chatbot has to disclose that it’s AI, synthetic content has to be labeled. (The €35 million or 7% tier covers outright prohibited practices and has applied since February 2025.) The full obligations for high-risk systems would only start at the end of 2027, though that delay is still being argued over.
Does this reach you? If you have a subsidiary or operations in the EU, or you sell a digital product to European users, you’re in. A pure commodity exporter, hardly. And if you’re in, this week’s job for legal and tech is an inventory: where is there customer-facing AI that doesn’t disclose itself, where is there generated content going out unlabeled.
THE MIRROR FROM CHILE
To bring it home, the first serious index of AI maturity among Chilean companies came out this week (CCS, Corfo and PMG, using MIT methodology across 740 companies). The result: 25% exploring, 66% piloting, 8% scaling and 1% leading. According to the authors, the pilots die of governance and management. Technology almost never shows up among the causes.
If your pilots have gone a year without scaling, the bottleneck is most likely organizational: who governs this and how the return gets measured. Buying the next tool won’t fix it, because the tool, as we just saw, will be cheaper and more capable every month.
In 1979 what came in without permission was a spreadsheet. What comes in now writes code on its own and, left alone, sets up its own message board. That’s what we work on at Velaria: helping companies know what AI is running inside, with which permissions, and what record it leaves. If you want to talk it through, hit reply and it comes straight to me.
